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Method and system for transferring content information and supplemental information 
relating thereto. 



The invention relates to a method of transferring content information and 
omental information relating there*,, in which method an encoded ^ . 
Zlten, information and a waterma* pattern representing supplemental tnformation ts 

transferred. „ of — «-*»^ 

and supplemental information renting there*, ta which an encoded signal is gene^rf by 
It^g the content information in accordance with a watermark patten, representing 

supplemental further relates to a method of retrieving supplemental " 

,0 information related to content information, in which a watermark paaem representing 
1 CTIn. information is retrieved from an encoded signal representing the content 

information and the watermark pattern. ....... 

The invention further relays to a system for transfers content 
, • „„ related supplemental information, an arrangement for generating an encoded 
15 STJ^SS— . - encoded signal, - encoded ,gnal. a control 

and a record carrier. 

Such methods and such a transfer system are described in patent _ 
,™ ™™« (PHN 15391). document Dl in the list of related documents. The 
20 -P«° ™^ ZL content is increasingly transmit and recorded in 
" irjCr^e, an MPHO hi..eam. There is a growing need » 

I^mental— ^ 

supplemental information is intended for ^g*^--^ ^ 

useful in copy protection applications. 

Copy protection has a long history in audio publishing. The presen y 
f . " ^ding PC's with audio cards, provide little protection against 
installed base of equipment, including 
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unauthorized copying. In any copy-proton scheme, the most difficult issue is tr* a pir*e 
can always attempt to playback an original disc, he can Tea. the cement as if .. were an 
TaloThome recording and record , I, is desirable that consumer recorders are * to copy 
^Igs of consumer's own creative productions without any limitation, but prohibit the 
5 recording of copy-righ, material. Tnus, me copy protection m echanism must be abte to 
Tdnguish between consumers' own creations and content that originates from profess.onal 
music publishers. The equipment must make mis distinction based on the audio or video 

signal only, as any reference to the physical source of content (e.g. disc or 
signal u m . „ nrr -codv hits" have been defined, which bits 

unreliable. For digital storage media such as DCC, copy oits na .,„_»■ 
,0 indicate a copyright status, e.g. "no copy allowed-, "free copy- or -one genera.cn of copy 
allowed", der copy bits may indicate that the medium containing the information must be a 
-professional" medium manufactured by pressing and no. a "recordable" disc. 

Marking the digital content signal, for example by a marker 
accommodated in such an encoded signal so as to classify the encoded signal as authentic^ 
,5 programme material, is referred to as watermarking. In our system the watermark takes the 
form of a multi-bit watermark pattern representing some supplemental information, e g. 
^calg that the encoded signal constibi.es copy protected content and/or indicate the ongu, 
of the content. A watermark usually has a fixed par. .o identify the bi. pattern », vafcd 
waKrmark and/or synchronising me retrieval process, and may comprise a — part 
20 presenting said supplemental information. A method is disclosed in DI or 
Jtermark pattern in the encoded signal such that i, is easy .0 detect, but diffi ult» erase 
modify without serious degradation of the quality of the audio or video content 
decodLg. Moreover, the watermark pattern has to be rdatively long to prevent an unrn^d, 
encoded signal from being classified accidentally as marked. Also the watermark shou* be 
a detectable in a refctivel, short time. e.g. 1 to 10 seconds, to enable a fast respond w en 
classifying a signal. Known watermarks have the disadvantage, that they represent only a 

Lacious party is stiU possible with only a limited degradation of die content after decodmg. 



30 



It is an object of the invention to provide means for transferring 
supplemental information related to content information such that manipulation of the 
supplemental information is countered more effectively. 
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For this purpose, the method of transferring according to the invention is 
characterized in that a control signal is transferred representing a control pattern, the 
watermark pattern and the control pattern in combination representing the supplemental 
information, and in that the watermark pattern comprises the result generated by applying a 
one-way function to the control pattern. The method of encoding according to the invention 
is characterized in that a control signal is generated representing a control pattern, the 
watermark pattern and the control pattern in combination representing the supplemental 
information, and in that the watermark pattern is generated by applying a one-way function 
to the control pattern. The method of retrieving is characterized in that the watermark pattern 
and a control pattern in combination represent the supplemental information, and in that the 
control pattern is processed by a one-way function, and in that the supplemental information 
is verified by comparing the watermark pattern and the processed control pattern. For this 
purpose, the arrangement for processing an encoded signal representing content information 
and a watermark pattern representing supplemental information, which arrangement 
comprises a retrieval unit for retrieving the watermark pattern according to the invention, is 
characterized in that the arrangement comprises a control unit for receiving a control signal 
representing a control pattern, the watermark pattern and the control pattern in combination 
representing supplemental information, and a one-way function unit for generating a 
processed control pattern and a comparator for verifying the supplemental information by 
comparing the watermark pattern and the processed control pattern. A record carrier 
according to the invention comprises the encoded signal and/or the control signal as recorded 
information. 

The above measures according to the invention have the effect, that a 
small change in the control pattern will result in a totally different processed control pattern 
due to the nature of the one-way function. When a malicious party manipulates the control 
pattern, the watermark no longer corresponds to the changed control pattern, or needs to be 
fully replaced. Hence manipulation of the control pattern can easily be detected during 
watermark verification in a player a recorder. Also a small change to the watermark pattern 
cannot be matched by also modifying the control pattern due to the nature of the one-way . 
function, which prohibits calculating the input data 'backwards' from a given output value. 
This is advantageous in that any changes to the control pattern or the watermark can be 
easily detected. If the malicious party wants to manipulate the supplemental information 
represented by the watermark and/or the accompanying control signal, he is forced to fully 
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repiace the watermark pattern, which will result in severe ioss of quaiity in the reproduced 
content, whereas even minor changes to the watermark pattern cannot he matched by 
calculating a corresponding control patten and will be detected also. 

It is noted, that a system for copy protection of recorded signals, an 
5 information carrier and reading device are known from EP-0545472 (document D2). The 
known system uses a physical mark representing supplemental information for controlled 
information reproduction. If the information is copied on a writable information earner the 
information of this copy will not be reproduced, because during the writing process on* the 
information is recorded and the copy itself does not contain the physical mark. A problem » 
10 the known system is mat it is not possible to allow a copy to be made which cannot be 

capied tether. In an embodiment of the sysKm according to our invention the above control 
pattern has the function of a copy permission mark, which is distributed along with the stgnal 
reproduced from an original recording. The recorder of mat embodiment does venfy the 
watermark in the signal against the copy permission mark. If tart marks correspond, the 
15 content is recorded on a recordable record carrier and thus a first generation copy » made, 
bu , the permission mark itself is no. recorded on the copy. So if the signal of the copy » 
reproduced, it no longer comprises the copy permission mark. The recorder win not make 
another recording from the signal from the firs, generation copy. Hence one and only one 

generation of copies can be made. 
, Q An embodiment of the arrangement for generating and/or processing an 

encoded signal according to the invention is chara«erized in that the one-way function umt „ 
arranged for generating a n-time processed control pattern by passing the control pattern 
times through a cryptographic one-way function, n being an integer > 0. 
effect, mat the encoded signal comprises a watermark pattern and a control s,gnal compnses 
25 a control pattern as a cryptographical.y controUed counter. The counter value rmphcrtly . 
represented by the control partem is determined comparing n-time processed control patterns 
and the watermark pattern until a mafch is found (or no matth is possible Ida. . 
predetermined maximum count). The counter is cryptographically decreased ,n ti,e p ayer 
before outputting the processed control pattern to a recorder. The recorder venfies the 
30 counter and. if the count permits, decreases the counter again and makes a recordmg _ 
including the processed control pattern. This has the advantage, mat a Hnuted number of 
generations of copies can be allowed, whereas copy control is effected in the P*« "^T 
Lrde, The decreasing is performed b, a cryptographic one-way taction 
invened without a huge, prohibitive computational effort, so increasmg sard counter value 
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virtuaUy impossible. As soon as the counter is decreased too often, the processed control 
pattern no longer matches the watermark. The player and recorder will then block 
reproducing and/or recording the information. 

Further advantageous, preferred embodiments of the system and 
arrangements according to the invention are given in the dependent claims. 



These and other aspects of the invention will be apparent from and 
elucidated further with reference to the embodiments described by way of example in the 
10 following description and with reference to the accompanying drawings, in which 

Figure 1 shows a copy control system and 
Figure 2 shows the one-way processing of a copy control pattern 

comprising two parts and 

Figure 3 shows a one-way function, 
15 Figure 4 shows a copy control system using a medium mark P and 

Figure 5 shows an arrangement for processing an encoded signal and 
Figure 6 shows a recording arrangement. 



2Q The general concept of the invention is adding a control pattern to a 

watermarked, encoded signal, while a one-way function is used for generating the watermark 
from the control pattern. This allows a check at the destination of the watermarked signal for 
the integrity of the watermark and the accompanying control pattern. This has several 
advantages, e.g. the watermark may be relatively short and does not need its own integrity 

25 check bits, it may be repeated every few seconds in the signal allowing a classification of 
parts of the signal after editing, etc. As the watermark has to match a processed control 
pattern generated by applying a one-way function, it is computationally not feasible to 
calculate the control pattern '•backwards" from a watermark. Tampering with control pattern 
and watermark is only possible by fully replacing both, which will result in serious 

30 degradation of the quality of the reproduced content. If a valid control pattern is not 

available/reproduction or recording of the encoded signal may be controlled or blocked in 
players and/or recorders complying with the copy-protecting rules. Preferably all devices 
available to the consumer check the watermark pattern and do not accept any signal without 
the control signal. A lot of applications may benefit from this control, e.g. copy control, 



WO 98/33325 £ PCT/IB98/00087 

6 

payment of copyright fees, music or video rental, etc. The copy control may be similar to 
said DCC copy bits. The presence of a control pattern may be required to allow playback, 
and/or to indicate the copyright status, e.g. allowing one generation of copies. Also a release 
after a certain date may be effected by distributing the control pattern separately after that 
5 date. Further any related information may be indissolubly attached, e.g. author, song text, 
titles, performers, or a period of use may be included in the control pattern. 

An embodiment of the invention is a system for copy protection allowing 
one generation of copies, also called copy-once. A professional audio stream contains 
embedded copy-right data that grants permission to copy once. This is implemented by 
10 embedding a watermark yeo in the audio stream. Moreover the professional disc contains-a 
special permission mark x M where Yca = H(0 with HO a cryptographic one-way function. 
The mark y„ remains with the audio (possibly embedded) during playback, but it is removed 
by the consumer recorder. A copy made by the recorder therefore does not contain the 
permission mark and cannot be copied. 
15 For the embodiments of the system a suitable relation between the 

watermark representing a bitpattern y and the control pattern x is a one-way function. An 
implementation of the one-way function can be y = x 2 mod N with N a public modulus. 
Here N is the product of two secret large primes (N = p q). In fact N can be part of the 
data that is embedded in the watermark, i.e., concatenated to y. Another possibility is the 
20 discrete-log one-way function conjectured by Diffie and Hellman [1976] (= document D4): 
F(x) = «* in GF(p) with a a primitive element of GF(p). Here p is a large prime such that 
p-1 has a large prime factor. The above two implementations bear the disadvantage that the 
size of the arguments, i.e., the number of bits needed to be secure, is quite large. A practical 
system based on fewer bits can be to apply an appropriate secret-key encryption algorithm, 
25 e.g. the DBS, with y = F(x) = x ® DES(x). This is illustrated in the circuit of Figure 3. 
Figure 3 shows an implementation of a one-way function generator based on secret-key 
encryption algorithm. On the input 31 the control pattern x is applied and processed in the 
encryptor 32 by using a key from a key input 33. The output of encryptor 32 is bitwise 
EXOR'd to the input x by logic unit 34, resulting in bitpattern y on the output 35. In this 
30 circuit, the key can be made public or included in the watermark, i.e. concatenated to y. 

A suitable watermark for an audio signal with the DSD format (see 
document D3) is embedded by forcing a small fraction (0.01 % to 1%) of the bits to specific 
values determined by W, This makes the detection simple, as a player or recorder only has 
to check the value of predetermined bits at predetermined locations. The artefacts caused by 
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bits forced to represent a watermark can be nunimized by noise shaping. We found for DSD 
that a watermark involving 1 % of the bits will reduce the signal-to-noise / distortion ratto by 
one dB for a SNR in excess of 1 10 dB. On the other hand, if an attacker changes the value 
of these bits, the SNR dramatically deteriorate by several tens of dBs. For video a suitable 
watermark is embedded in the compressed MPEG, e.g. in the picture type (PTY 

watermarking, described in Dl). 

A further embodiment of the invention is a system for copy protection 

allowing one n generations of copies, also called copy-control with copy-n-times feature. 
Ms embodiment for copy protection of recorded signals allows a limited number of coptes. 
in our concept, professionally released titles contain at least two different types of copy- 
control marks: a watermark embedded in the content, and a copy-control 
(validatioa/aumorization) control pattern attached to the content but removable and 
modifiab.e by recorders. Said contro! pattern is called a copy^onttol ticket. The ticket in the 
digital signal stream is modified every time that the signal passes a record or playback 
device A cryptographic relation between the watermark and ticket is verified during each 
piayback and each recording. An optional third type of copy-control mark, a earner pattern 
representing a medium mark identifying the medium (disc/tape/«c), may be applied 
separately or may also be reiated to the same watermark. A medium mark can be represented 
for instance by a wobble groove or a pit jitter modulation, and it preferably also is dually 
detectable. Recordable media may carry a fixed predetermined medium mark identi^ing the 
medium as recordable, or as a professional disc from a known source. A separate check may 
be made for the medium mark, which may be a predetermined value or a value related to the 
watermark and/or the ticket via a cryptographic function. In the total system concept, we 
distinguish 

o Seed U: a random number generated by the content owner. 

. A medium mark P ftat is present on professionally released discs/storage metha; 
recordable media carry a predetermined value of P. 

= A watermark W, embedded in the content. W can simultaneously exist in all digital 
representation formats (audio in DSD format, bi, stream, PCM, or video MPEG etc.) as 
, well in an analogue version. If tins concept is appHed to video, an analogue watermark 
can for instance be combined with ticket, represented in Vertical Blanking Interval The 
digita! watermark can be represented bom in the MPEG PTY (Picture Type) sequence 
and in the pixel domain, the ticket can be stored in user.da* fields of a GOP (Group Of 
Pictures) header. User home recordings (not subject to copyright) can be distinguished as 
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such through the absence or predetermined values of W. 
o A Copy-Control Ticket T which plays the role of a cryptographic counter. T is a small 
data field that is present in the data headers, e.g. added to the signal in a similar manner 
as said DCC copy control bits. T typically contains 40 to 1000 bits. 
5 in the total system concept, Ticket T in the stream is replaced by T' = F<T) during each 
recording or playback operation, whereby F is a publicly known cryptographic one-way 
function. That is, neither the player nor the recorder pass T transparently but feed it through 
function F. Our scheme exploits the invention that T can be regarded as cryptographic 
counter, which can easily be incremented but cannot be decrement unless an attacker can 
10 invert F. From a cryptographic point of view it is not necessary that F is kept secret to 
potential attackers. Here we aim at restricting the length of the copy paths, e.g. to prohibit 
generation of copies of copies of copies, i.e. the number of generations. Playback is allowed 
only if the watermark in the stream matches F»<T) where m is the number of sequential 
recording or playback operations that are still allowed. Typically m is odd. Recording is 
15 allowed only if the watermark in the stream matches F»(T) where m is the number of 

sequential recording or playback operations that are still allowed. Typically m is even. In the 
above statements m may either be available explicitly, or the device may check all m which 
are reasonably small, e.g. m < 4 if copy once is the maximum number of copies allowed to 
made anyhow. An example of a possible cryptographic one-way function is described above 

20 with reference to Figure 3. 

In an embodiment the number of parallel copies from one original is restricted. 

The above concept is extended and applied to restrict the number of parallel copies made 
from one disc, e.g. if customer is only allowed to copy directly from the original disc that he 
bought from the publisher, and the number such copies is restricted. To this end we need a 

25 small recordable area on each professionally released title to store and update T. The basic 
idea is that the player modifies T into F(T) every time that the player authorises a recorder 
to make a copy. In such case the original disc as sold by the publisher is produced by ^ 
initially generating a seed U. From this seed, the following variables are computed: P- 
F(U) and T=F( F(U) ) which we denote as F*(U). For a disc that the customer is allowed to 

30 copy'n-times in parallel, a watermark W is created as W = F~»(U>. The player outputs the 
contents, but not T during normal operation. During recording the recorder asks the player to 
provide a ticket T such that W= F(T), which is also recorded on the recordable disc. The 
player reads T from and replaces it by F(T). The player only provides F(T) to the recorder if 
the player reads from an original disc, i.e., with a valid P matching T. The recorder 
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iteratively replaces T by F(T) until W=F<T). The content with embedded W and appropriate 
T are recorded to disc. If the player reads a recordable disc, T is never released to the 
outside. 

A copy control concept is disclosed that relies on physical marks on the 
5 medium, watermarks embedded in the content and a copy control ticket that is represented as 
a digital' number. It is to be noted, that this concept embodies two separate mechanisms: a 
watermarked content in combination with both the control ticket T and a medium mark P. 
Obviously the concept of using a control ticket in combination with a watermarked signal can 
be applied separately in a system for transferring content, e.g. in a broadcast system or on 
10 internet. Basically the control ticket provides a counter which can be incremented but not 
decremented. The control ticket concept is particularly suited for the watermarking of DSD 
audio as described in document D3. The concept of embedding data into the LSB bits and 
reducing their artefacts by noise shaping can also be applied to Pulse Code Modulation 
audio. The idea can also be applied to MPEG video storage of DVD. The watermark can be 
15 stored in GOP structure by modifying the PTY sequence. In addition an identifier of the 
recorder may be included in W or in a separate watermark W, Preferably each home 
recorder includes such an identifier when making a recording of unmarked material. The 
identifier may be just a manufacturer code, type and serial number of the recorder. 

Figure 1 shows a copy control system according to the invention. The music 
20 content on a record carrier 1 1 is watermarked by a watermark pattern W, while the record 
carrier 11 further comprises a control pattern, the copy control ticket T. The player 12 
comprises the usual elements for reproducing the music from the record carrier, e.g. known 
from a CD player, and verifying means comprising three one-way function units 121,123,124 
comprising a one-way function F (see description with reference to Figure 3) and two 
25 comparators 122,125, which may be implemented in a single calculation unit, e.g. a 
microprocessor and a program. The watermark W and the ticket T are derived from the 
original record carrier 11. The ticket T is coupled to one-way function unit 121 resulting in 
T which T' is coupled to first comparator unit 122 and a second one-way unit 123, which 
has its output T" coupled to a third one-way unit 124 resulting in T» coupled to a second 
30 comparator unit 125. Both comparator units receive the watermark W on a second input for 
comparison. If the first comparator unit 122 finds equality, then playback is allowed, but no 
(further) copying. If the second comparator unit 125 finds equality, then playback is allowed 
and one copy generation is still possible. If both comparators find no equality no playback 
allowance is given. The player has an output to a digital interface 13, e.g. a IEC 958 or ^ 
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1394 digital interface, for outputting the content information comprising the watermark W 
and the processed ticket T\ The recorder 14 has an input for receiving said signals from the 
digital interface 13. The watermark W is coupled to a third comparator unit 133. The ticket 
T is coupled to a fourth one-way function unit 131, resulting in a processed ticket T", 
5 which T" is coupled to a fifth one-way function unit 132, resulting in T" coupled to the 
third comparator unit 133. If the third comparator unit 133 finds equality between T'" and 
W, copying is allowed and the music content comprising the watermark W and the two times 
processed ticket T" are recorded on a recordable record carrier 15. So one generation of 
copies is allowed when the 3-time processed control pattern T" equals W. The resulting 
10 copy comprises a 2-time processed control pattern T", which allows playback of this first 
generation copy, as the player will first generate a 1-time processed pattern, i.e. <T")\ 
which will now match the watermark pattern W. Further recording of the music content is 
blocked by the recorder, as the 5-time processed ticket does not match the watermark. Even 
if a tampered recorder is used by a malicious party, the resulting copy comprises a 4-times 
15 processed ticket T"" as presented by the player. Such a copy cannot be played on a 
compliant player, as the first and second comparators will not find equality. So both a 
recorder and a player need to be tampered with to create and use illegal copies. 

In an embodiment of the transfer system the n-time processed control pattern 
constitutes a cryptographically protected counter. This counter may be used for counting a 
20 number of times that an encoded signal is permitted to be played back, e.g. in a audio or 
video rental system, or recorded, e.g. for counting so called parallel copies. In such 
applications the control signal is preferably stored and updated on the record carrier itself, 
but may alternatively be stored separately, e.g. in the playback and/or recording device or on 
a chipcard. Also a number of control signals may be stored, whereas for each action to be 
25 controlled one of the control signals is destroyed or made unaccessible, e.g. on an optical 
disc by applying or removing ink in the respective area. 

Figure 2 shows the one-way processing of a control pattern T*" 1 comprising 
two parts. The first part 21 is a seed and the second part 22 is an info part comprising 
supplemental information, such as the name of the author, the owner, a release date, etc. 
30 Both parts 21,22 axe combined in combination unit 23, e.g. concatenated, added or EXOR'd, 
and the result is coupled to a first one-way function unit 24. Control pattern T° comprises 
again two parts, the first part 25 being the output of the first one-way function unit 24, and 
the second part 26 being the same as info part 22. For the next one-way processing cycle the 
same functions are applied, i.e. a further combination unit 27 and a further one-way function 
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unit 28 resulting in a control pattern T- again comprising two parts. Ate a predetermined 
IIS or one-way cyc.es the firs, part of the patiem front the output of the one-way unt, 
v , 0jm ,he watermark as with the previously described embodiments. This has the 
advantage, that the info part 22,26 of each generation control pattern is directly readable and 
1 protected agains, manipulation, as any smaU change in the info par, will comply 
^ e me resulting patiem at the output of the one-way units during the verificauon. to«he 
even, of an encrypted encoded signal, the info par, may comprise me decrypt™ toy The 
*Tpart 22 may also comprise an explicit counter value, which has - be decrea^d be*. 

'sing me nex, (» + l)-time processed control pattern. The expUcit counter value p then 
£L L number of processing cycles of the one-way unit Tnis has the -~ ~ 
only me p-time processed control pattern needs to be compared to the watermark patter, 
course a predetermined change, such as an explicit counter value included m the rnfo part. 
Ha, t0 be changed during generation and verification in the same way. Hence tampenng wtth 
such predetermined changing values is effectively prevented. 

Figure 4 shows a copy con.ro. syaem using a medium mark P. The medtum 
mark auows two sepanue conditions to be verified for an original disc before PW-*» 
Iwed The record carrier 41, e.g. an optica, disc, comprises a further modulauon pattern 
" Jalons of „ physical parameter representing a medium mark P refc*d - 
pattern W the further modulation pattern being of a different type than the mediation 
,ZL An example of further modulation pattern, such as a wobble of a track, can be found 
L D2. According to the invention, me medium mark P is coupled «o a one-way urn, 4* 
having an output coup.ed to a first comparator 423 and/or a second compete ,424^ 
one-way units comprises a cryptographic one-way function, e.g. as desenbed 
to Figure 3. The first comparator 423 also receives the watermark w. £. 
; first condition for a no-copy original disc is detect. The second ™ 
the control ticket T, and a, equality a firs, condition for a copy-once allowed d s= rs detect^ 
r,cket T is a*, coupled to a second one-way uni, 425 resuiting in T. whtch T- „ coup.e* to 
a third comparator 426, which also receives the watermark W. A, equality the second^ _ 
condition for a n«op, original disc detected, or a legal firs, generation copy »«--0» 
0 which case the medium mark P may be absent or has a predeternnned value . The -time 
processed ticket T is coupled also to an output of the recorder on dtgtta, tnterface 43, and » 
a third one-way unit 427, which is coupled to a fourth one-way unit 428. resulting » a 3- 
time processed ticket T"\ which is coupled to a fourth comparator 429 atso recede 
watermark W. At equality the second condition for a copy-once allowed dtsc „ detect. 
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When the colons for playback are ^ed, the music content including ~* W 
H*— from the player 42 to the digital interface 43. A recorder 44 may be coupled to 
IdTgital interface 43 for recording the music. The watermark W and the ticket 
ZJL are verified in the same way as in the recorder described with reference to Ftgure 

m an embodiment the player 42 and the recorder 44 have an input 431.441 for 
a nome wafcrmark W„. In me player me home wa*rmark W„ is coupled to a «"> 
comparator 430, which also receives the watermark. A, equality a home personal creauon ,s 
ZLd The input 431 is preferably coupled to said fifth comparator 43. va a further one- 
" i" "hich case the home seed value is to be supplied to the mput of *e further one- 
way U ni, The home seed value or watermark may be stored in a memory of the 
p4/-orde, or on a separate memory module, e.g. a chipcard, or may be kept on paper 
and entered via a keyboard by the user like a PIN code. Alternatively recordmgs of 
consumer's personal audio creations can be recognized and distinguished, because then- 

waKrmark is a fixed watermark, e : g. the all-zero word. 

in an embodiment of the system the encoded stgnalts encrypted, wluleP is 

used for decryption, shown as optional decryption unit 422 connect between the read stgnal 
an^e signTcarrying the plain contents including W and ticket T. This is advan«geous for 
orotecting the disc against urtcontrolled dati. retrieval or bit-to-bi. copymg, e.g. on a 

for making a master disc, which mas*r disc is used for multip.ying the " ^ 
aevice may men generate and output the watermark .pattern by applymg a forth, one way 
action on me earner patiem. This has the advantage, mat the earner 
available outside the masKring device, while the mastering dev.ee cannot be J> 
produce a disc with a predetermined carrier pattern (e.g. extracted from a source dtsc to be 
reproduced by a malicious party). 

The control pattern or ticket may be recorded along with the content 

natively a separate location not directly accessible to a malicious party 
information, or alternatively a separate r.rn nrDVD The 

ro ay be selected, e.g. located in file headers or in the lead-m section o, a CD o DVTX Th 
Jy-contiol ticket can be hidden in the MPEG video stream. In an embodnnenuhts data 
JL in the GOP header, in tire <~ ™™ "~ 

compression standard). , 

Figure 5 shows an arrangement for processing an encoded signal. The 

u • 52 for playing an optical disc 5 1 . The player is provided with 

arrangement shown is player 52 tor piaying <u v 
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read means comprising a read head and a servo/control unit 58 for reading informal from 
the disc 51. The player has a digital output 53 to a digital bus for outputting the retneved 
content signal including the watermark W and a processed control ticket T. A further analog 
output 54 for connecting a headphone or other audio equipment may be provided for 
5 outputting the music content after processing by a D/A converter (optional, not shown). The 
signal read from the disc 51 is processed by read unit 55, which may be provided wxth a 
decrypt function as described with reference to Figure 4. The read unit 55 is coupled to a 
retrieval unit 61 for retrieving the watermark pattern W, and to a further retrieval umt 60 for 
recovering the control pattern T. Watermark W and control pattern T are connected to 
L0 control unit 62. The control unit 62 is provided with a one-way unit comprising the 
cryptographic one-way function F (described, above with reference to Figure 3), which 
function F can be applied n times to generate an n-times control pattern T°, and a comparator 
unit for comparing the processed control pattern T» and the watermark. The 1-time processed 
control ticket T' on output 57 of the control unit 62 is switched to the digital output 53 
15 together with the watermarked content signal via a switch 56, which switch 56 is operated by 
the control unit 62 in dependence of a verification process. Hence the output signal 
representing the content information is only available on output 53 in dependence on the 
supplemental information represented by the watermark in combination with the control 
ticket. The following checks are performed in the verification: W = F<T) or W - F <T) 
20 indicating that playback is allowed, or possibly further repeated tests up to W - F*-<T). 
The first successful test of a n-times processed control pattern T» equals W indicates a 
counter value m of the control pattern. The counter value m can be used to verify the 
generation of a copy in a system allowing n generations of copies, or the number of times a 
certain act is allowed (e.g. pay per use for a software program), or any other application 
25 needing a secure counter. In an embodiment of the player a carrier pattern read umt 59 is 
provided for retrieving a medium mark P from the record carrier, e.g. from the servo signals 
of servo unit 58 for a wobble pattern as described in D2. The medium mark P is connected 
to the control unit 62, wherein a further check T = F(P) is performed for verifying the 
control pattern T and the physical mark P. The medium mark P may be coupled to an 
30 optional decryption unit in read unit 55. If encryption has been applied to the disc content, 

the player decrypts the stream, using P. 

Figure 6 shows a recording arrangement. The arrangement is a recorder 65 for 
recording a recordable disc 66. The recorder has a digital input 72 from a digital bus for 
receiving a signal to be recorded including a watermark W and a control ticket T. The input 
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72 „ coupled to a retrieve unit 69 for relieving the watermark pattern W. and to a further 
^1 70 for — , d. control pauem T. Wa*rma* W an, con^ol P^n T 
retrieval uru The control unit 71 is provided with a one-way unit 

means 73 togeiner wiui . _ tt..-. t u e output of 

, -t 71 in deoendence of a verification process. Hence tne ouiyui u 

^ 5 . r l n orocess is positive and indicates that a copy may be made. The 
disc 66, if the venfication „ . ta control unit 

~« to ^ "* Z ZTiTc IpytisL audio is allowed if the wa^rma* 

71 bef ° rc ^ ^"tLodilt « more generations of copies, 

in the stream matches W - wrtrder and record audio even 

W - F-(D is checked. If an attacker manages to modify his recorder and recor 

W _ F (T) is ch a nonnal player wm reject to playback the disc. In 

if the appropriate T is not present, a normal v j 

! uv w a professional title is produced by initially generate a seed U. From 
professional publishing a profession v T =(F(F(U)) which we 

this seed, the following variables are computed. P- GOD. «* ^ a w „k W is 

T*nn For a disc that the customer is allowed to copy n-times, a watermar 
denote as F 2 (U). For a aisc ui<u soecified such that 

w - F^-'rn The one-way function G and variable P may be specineo 
3 created as W - F CD- The y ^ ^ Tf 

P also contains an identifier for the pubhsner o 

ur v, ott^mnt, to write a particular P, in order to make a bit-exact copy or 
a pirate publisher ^ ^ professionally 

copyri ght disc, ^ — « ^ n , ^ me ab ove cryptographic relation, 

released disc contains P, T^W J» ^ recorda ble media contain 

>5 Legal copies of professionally released ^copy S \ In case m = 1, 

W and a « X - - W ^^J^^of pr— y 
.e content of W and a tic*et T such that W 

(CO r T 6 * « ™ = 2, the content may be recorded and played bac k 

= F^CT), with m = 2, 4, o,.-. a" ^ 

30 one more time. ncincr a disc as 

Although the invention has been explained by an embodtment usrng d» 
„• ; will be clear that other systems for transferring information can be 
recordtng medtum, ^ ^ ^ sjgnal wi ^ ^ signal may be 

employed in the invention. For example, 
transferred via a data-network like the internet. 
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Whilst the invention has been described with reference to preferred 
embodiments thereof, it is to be understood that these are not limitative examples. Thus, 
various modifications may become apparent to those skilled in the art, without departing 
from the scope of the invention, as defined by the claims. For example, the encoded signal 

5 might be distributed on a read-only disc or tape, while the control signal might be distributed 
separately. Further a watermark in the analog domain may also be employed, although in 
general such watermarks are more difficult to retrieve. Unlimited use of the control signal 
might be prevented by encrypting the control signal by a key known to the destination only, 
e.g. a key build in specific reproducing devices or a public key supplied by the destination 

10 using a public key system (e.g. RSA). Also the encoded signal and/or the control signal may 
additionally be protected by scrambling or encryption methods, or may be additionally 
provided with a digital signature. A free-copy ticket R, which is a digital signature over (part 
of) the content and/or the watermark W may be employed. Further, the invention ties in each 
and every novel feature or combination of features, including those within the mentioned 

15 incorporated or related documents. 
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CLAIMS: 



1. Method of transferring content information and supplemental information 
relating thereto, in which: 

an encoded signal representing the content information and a watermark pattern representing 
supplemental information is transferred, characterized in that a control signal is transferred 
representing a control pattern, the watermark pattern and the control pattern in combination 
representing the supplemental information, and in that the watermark pattern comprises the 
result generated by applying a one-way function to the control pattern. 

2. Method of encoding content information and supplemental information relating 
thereto, in which: 

an encoded signal is generated by encoding the content information in accordance with a 
watermark pattern representing supplemental information characterized in that 
a control signal is generated representing a control pattern, the watermark pattern and the 
control pattern in combination represent the supplemental information, and in that the 
watermark pattern is generated by applying a one-way function to the control pattern. 

3. Method of retrieving supplemental information related to content information, 

in which: 

a watermark pattern representing supplemental information is retrieved from an encoded 
signal representing the content information and the watermark pattern characterized in that 
the watermark pattern and a control pattern in combination represent the supplemental 
information, and in that the control pattern is processed by a one-way function, and in that 
the supplemental information is verified by comparing the watermark pattern and the 
processed control pattern. 

4 system for transferring content information and related supplemental 

information via a transfer signal comprising an encoded signal, the system comprising a 
transmitter for transmitting the transfer signal, which transmitter comprises an encoding unit 
for generating the encoded signal by encoding the content information in accordance with a 
watermark pattern representing supplemental information, and a receiver for receiving the 
transfer signal, which receiver comprises a retrieval unit for retrieving the watermark 
pattern, characterized in that the transfer signal further comprises a control signal 
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representing a control pattern, the watermark pattern and the control pattern in combination 
representing the supplemental information, and in that the transmitter comprises a one-way 
function unit for generating the watermark pattern in dependence on the control pattern, and 
in that the receiver comprises a further one-way function unit for generating a processed 
5 control pattern and a comparator for verifying the supplemental information by comparing 
the watermark pattern arid the processed control pattern. 

5. Arrangement for generating an encoded signal, which arrangement comprises 
an encoding unit for generating the encoded signal by encoding content information in 
accordance with a watermark pattern representing supplemental information, characterized in 

10 that the arrangement comprises a control unit for generating a control signal representing a 
control pattern, the watermark pattern and the control pattern in combination representing 
supplemental information, and a one-way function unit for generating the watermark pattern 
in dependence on the control pattern. 

6. Arrangement as claimed in claim 5, characterized in that the arrangement 

15 comprises a transfer unit for generating a transfer signal comprising the encoded signal and 
the control signal. 

7. Arrangement as claimed in claim 5, characterized in that the one-way function 
unit is arranged for generating a n-time processed control pattern by passing the control 
pattern n times through a cryptographic one-way function, n being an integer > 0. 

20 g. Arrangement as claimed in claim 7, characterized in that n = 3 indicating that 

one generation of copies is allowed. 

9. Arrangement as claimed in claim 5, characterized in that the arrangement 

comprises an identification unit for including a recorder identification code in the 
supplemental information. 

25 10. Arrangement for processing an encoded signal representing content information 

and a watermark pattern representing supplemental information, which arrangement 
comprises a retrieval unit for retrieving the watermark pattern, characterized in that the 
arrangement comprises a control unit for receiving a control signal representing a control 
pattern, the watermark pattern and the control pattern in combination representing 

30 supplemental information, and a one-way function unit for generating a processed control 
pattern and a comparator for verifying the supplemental information by comparing the 
watermark pattern and the processed control pattern. 

11. Arrangement as claimed in claim 10, characterized in that the one-way 

function unit is arranged for generating a n-time processed control pattern by passing the 
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control pattern n times through a cryptographic one-way function, n being an integer > 0. 

12. Arrangement as claimed in claim 11, characterized in that the control pattern 
comprises a first part and a second part, and in that the arrangement comprises a 
combination unit for combining the n-time processed control pattern and the second part of 
the (n-l)-time processed control pattern, the output of the combination unit being coupled to 
the input of the one-way unit. 

13. Arrangement as claimed in claim 11, characterized in that the arrangement 
comprises a control unit for outputting a further control signal representing the n-time 
processed control pattern, n being equal to 1. 

14. Arrangement as claimed in claim 11, characterized in that the comparator is 
arranged for determining a value m by a first comparison of the watermark pattern and the n 
time processed control pattern at n=l and at least one further comparison of the watermark 
pattern and the n-time processed control pattern at n> 1, m being the value of n resulting in 
a successful comparison. 

15. Arrangement as claimed in claim 10, characterized in that the arrangement 
comprises an output unit for outputting an output signal representing the content information 
in dependence on the supplemental information. 

16. Arrangement as claimed in claim 15, characterized in that the output unit is a 
recording unit for recording the output signal on a record carrier. 

17. Arrangement as claimed in claim 13 and 16, characterized in that the 
recording unit is arranged for recording the further control signal. 

18. Arrangement as claimed in claim 14 and 15, characterized in that the output 
unit is arranged for outputting the output signal if m= 1 or m=3. 

19. Arrangement as claimed in claim 14 and 16, characterized in that the 
recording unit is arranged for recording if m=2. 

20. Arrangement as claimed in claim 10, characterized in that the arrangement 
comprises a playback unit for inputting the encoded signal from a record carrier. 

21. Arrangement as claimed in claim 10, characterized in that the arrangement 
comprises a carrier pattern read unit for retrieving a . carrier pattern from the record carrier 
and a one-way function unit for generating a processed carrier pattern and a comparator for 
comparing the watermark pattern and the processed carrier pattern. 

22. Encoded signal for use in the system of claim 5, which encoded signal 
represents content information and a watermark pattern representing supplemental 
information, characterized in that the watermark pattern comprises the result of a control 
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pattern processed by a one-way function, the watermark pattern and the control pattern in 
combination representing supplemental information. 

23. Control signal for use in the system of claim 5, characterized in that the 
control signal represents a control pattern for controlling an encoded signal representing 

5 content information and a watermark pattern, the control pattern, and the watermark pattern 
in combination representing supplemental information, which watermark pattern comprises 
the result of the control pattern processed by a one-way function. 

24. Record carrier carrying thereon the encoded signal as claimed in claim 22 
and/or the control signal as claimed in claim 23, 

10 25. Record carrier as claimed in claim 24, characterized in that the watermark is 

indicative for a n-times control pattern, which n- times control pattern after processing n 
times through a cryptographic one-way function corresponds to the watermark, n being an 
integer > 0. 

26. Record carrier as claimed in claim 24 or 25, characterized in that the record 
15 carrier comprises a carrier pattern, the watermark pattern comprising the result of the carrier 

pattern processed by a one-way function. 

27. Record carrier as claimed in claim 26, wherein the encoded signal is 
represented by a modulation pattern of variations of a physical parameter, characterized in 
that the record carrier comprises a further pattern of variations of a physical parameter 

20 representing the carrier pattern in a different way than said representation of the encoded 
signal. 

28. Record carrier as claimed in claim 24, characterized in that said record carrier 
is of an optically readable type, the encoded signal being represented by a modulation pattern 
of optically detectable marks in a track. 
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